AI Regulation: ECRs’ Perspectives is a CREATe blog series featuring the work of early career researchers who are exploring the contemporary challenges of AI regulation. Based on research presented at the AI Regulation ECR Conference, each post provides a concise and accessible insight into emerging legal and policy debates around artificial intelligence.
The series continues with a blog post by Ines Neves. Ines holds a PhD in Law and is an Invited Assistant Professor at the Faculty of Law of the University of Porto (Portugal). She is also an Associate at CEJURE, the Portuguese State Legal Centre, an Integrated Researcher at CIJ, and a practising lawyer. Her research focuses on Constitutional Law and Fundamental Rights, European Union Law, and Economic Law, with a particular interest in the twin green and digital transition.
Beyond Risk Classification: Worker-Centred Governance of AI in Industrial Workplaces
Overview
In industrial and business contexts, the application of artificial intelligence (AI) systems and models gives rise to intricate questions of permissibility, conditions, and limits that cannot be sufficiently addressed by the risk-classification model of the AI Act in isolation. Although not inherently antagonistic, innovation and fundamental rights require a framework that extends beyond the logic of product safety, incorporating the socio-technical and relational dimensions of AI. This blog argues that a worker-centred approach, grounded in participation and procedural safeguards, rather than in prohibitions and a ‘comply or be sanctioned’ approach, offers a means to reconcile innovation with the effective protection of fundamental rights.
1. Framing the Problem and the Legal Pathways
AI systems and models display a multiplicity of applications in industrial and business contexts (see, among others, Deshpande et al., 2021; Gabsi, 2024; Jarota, 2023; Özkiziltan & Landini, 2025; Shah & Mishra, 2024; Todolí-Signes, 2021; Vukićević & Petrović, 2023), with varying impacts on workers’ fundamental rights. These applications extend beyond the prohibited AI practices and the high-risk systems established in the AI Act and may, in fact, be particularly beneficial for workers’ health and well-being, as illustrated by the use of AI in ergonomics (Jeganathan, 2025; Larez & Maribao, 2025; Trstenjak et al., 2025). The insufficiency of the AI Act’s classificatory model stems from a normative architecture grounded in product safety, into which fundamental rights have been grafted in a manner that does not adequately accommodate the specificities of AI, not only as a system, but also as a reality embedded in organisational and relational contexts (Guaman Morocho & Galvis Correa, 2025).
The blog proposes guiding principles for framing the innovation-fundamental rights relationship, without treating them as necessarily antagonistic, and moving beyond the product safety approach adopted by the European legislator in the AI Act. Without prejudice to the product dimension of AI systems, these are also realities closely interwoven with social and labour relations. The fundamental rights framework of the AI Act, which is centred on the developer, the deployer, and AI as a product, is therefore insufficient to ensure respect for the fundamental rights of the end user or of those affected by AI systems, taking into account their nature as a unitary phenomenon with both technical and social dimensions (Jarota, 2023; Minotakis, 2025; Özkiziltan & Landini, 2025).
This research thus supports the strengthening of labour law, not through the introduction of prohibitions or a rigid rule-exception model – both of which have the potential to be detrimental to innovation and proportionality – but rather through enhanced mechanisms of effective worker participation in the design, development, deployment, and use of AI systems (Aloisi & De Stefano, 2023; Pereira et al., 2025), without undermining innovation or the advantages of such systems. Such an approach would ensure not only transparency but also trust and democratic representativeness in decisions that go beyond the scope of the freedom to conduct a business, affecting fundamental personality rights that require worker involvement.
2. The EU’s Role in Social Policy and Fundamental Social Rights: Beyond Questions of Competence
Despite the fact that, in the field of social policy, the European Union (‘EU’) has competence only in the areas defined in the Treaty on the Functioning of the European Union (Article 4(2)(b) TFEU), Articles 151 and 153 TFEU allow the Union to support and complement the action of Member States in improving the working environment and working conditions (Article 153(1)(a) and (b)), through the adoption of directives (Article 153(2)(b)), under the ordinary legislative procedure (see, among others, Opinion of the Advocate General and Judgment in case C-19/23, Denmark v Parliament and Council (Salaires minimaux adéquats). In the present case, none of the exceptions set out in Article 153(5) TFEU (pay, the right of association, the right to strike, and the right to impose lock-outs) apply. Instead, the primary concern is the safeguarding of fundamental social rights as outlined in Article 151 TFEU. In this regard, the European Union has been proactive in its efforts, having reinforced its actions in 2017 through the establishment of the European Pillar of Social Rights, followed by the formulation of an Action Plan in 2021. This approach formally recognised the necessity to address challenges arising from societal, technological, and economic developments, and to update the EU strategic framework on occupational safety and health. It also took into account the impact of digitalisation on the very notion of the working environment, as well as on the nature and content of work, and the associated psychosocial, organisational, ergonomic, and safety risks.
Furthermore, the right to fair and just working conditions is expressly enshrined in Article 31 of the Charter of Fundamental Rights of the European Union (‘CFR’), on an equal footing with the freedom to conduct a business (Article 16 CFR). It follows that the European Union is no longer merely a space of economic integration, but also a community of law responsible for the protection of fundamental rights, of both workers and undertakings, placing innovation at the service of maximising fundamental rights and societal well-being.
In the EU Strategic Framework on Health and Safety at Work 2021-2027, the European Commission acknowledges that EU legislation on occupational safety and health, including the Framework Directive and various specific directives adopted over time, already covers many of the risks arising from evolving industries, equipment, and workplaces. In parallel, both the Machinery Regulation and the AI Act have been adopted, with the objective of addressing the risks arising from new digital technologies. Nevertheless, considerable technological advancement calls for legislative refinement, with particular emphasis on the notion of Industry 5.0 (Alves et al., 2023) and the necessity for a vision that empowers European industry to spearhead the green and digital transitions, while harmonising workers’ rights and needs with technological progress and planetary boundaries.
3. AI in the Workplace: Regulatory Gaps and Illustrative Use Cases
The impact of AI on the legal sphere of workers is not, however, limited to health and safety (Todolí-Signes, 2021). The triad established in the AI Act – health, safety, and fundamental rights – already demonstrates a certain autonomy of the latter. While health and safety may be subsumed under fundamental rights, these rights do not exhaust their scope, which includes additional dimensions requiring protection and regulatory framing. These dimensions may lie very close to workers’ private and intimate sphere, which does not thereby become a social sphere more open to interference, merely by virtue of the employment relationship.
Consequently, it would be reasonable to anticipate that the AI Act would serve as a regulatory instrument designed to ensure that the development, placing on the market, putting into service, and use of AI systems adheres to human-centred principles. Indeed, the legislation in question establishes several prohibitions, requirements, and obligations. However, its scope remains circumscribed, as is necessary, particularly with regard to prohibitions, given the impossibility of anticipating the full richness of life and its grey areas without risking disproportionality or arbitrariness. Furthermore, the Act’s emphasis on requirements and obligations is indicative of its macro nature as product safety legislation, which is ill-suited to accommodate the specificities of fundamental rights and AI as a socio-technical reality.
To illustrate this point, it should be noted that several AI systems and models will fall outside the scope of the AI Act due to the adopted risk-classification system. Consider a logistics management use case in which AI is deployed to detect and identify objects within an industrial environment, with a view to optimising decisions and processes, and is capable of incidentally capturing images of workers subject to blurring. Even if developed in-house for internal use, the system falls, in principle, within the broad definition of an AI system under the AI Act, bearing in mind that “putting into service” includes internal deployment (see Article 2(1) and definitions in Article 3). However, such a system will not be prohibited under Article 5 nor generally qualify as high-risk under Annex III (pursuant to Article 6(2) AI Act), provided that its purpose is limited to object identification and does not extend to monitoring or evaluating workers’ behaviour or performance. In this scenario, the system can be characterised as minimal risk, with the consequence that the AI Act imposes no substantive obligations.
A similar conclusion arises in the case of an AI system designed to analyse workers’ postures, movements, and physical strain in order to identify and correct harmful patterns, such as repetitive or asymmetrical movements that may lead to injury, thereby preventing musculoskeletal disorders.
Ergonomic AI systems in industrial environments
Even where it involves data, including potentially sensitive data, such a system for ergonomic purposes, based on the extraction of keypoints (i.e. abstract representations of the human body derived from joint positions rather than full visual images), will likewise not be prohibited under Article 5, nor, provided it is not used to monitor or evaluate workplace behaviour, fall within the list of high-risk systems in Annex III.
These examples support the hypothesis that, by being built on a logic of product safety and market harmonisation, grounded in Article 114 TFEU, the AI Act adopts a predominantly compliance-based and sanction-oriented framework, focused on the objectives of health and safety. As such, fundamental rights remain secondary or only indirectly reflected in certain prohibitions and in the risk-classification approach.
The legislator itself recognises this limitation. As stated in Recital 9, the scope of the Regulation is limited when considered in the context of employment and worker protection. That is to say, it does not affect EU social policy law or national labour law compliant with EU law. This includes rules on working conditions, health and safety, and labour relations. Furthermore, it does not appear to compromise fundamental rights such as the right to collective bargaining, the right to strike, or other forms of collective action. Instead, the AI Act serves to supplement existing frameworks by introducing specific obligations (e.g. transparency, technical documentation, and record-keeping), while allowing Member States to adopt additional measures that pursue legitimate public interest objectives, provided that these fall outside the scope of the Regulation or pursue different aims.
4. From Risk Classification to Worker-Centred Governance
In view of the aforementioned points, the discourse should transition from the inadequacy of the AI Act’s normative architecture to the adequacy, sufficiency (in light of the principle of prohibition of insufficient protection (Untermaßverbot)), and proportionality of prevailing labour legislation. Whilst the AI Act may be insufficient to ensure adequate protection of workers, particularly given the opacity and technical complexity of AI, which may reinforce dynamics of power, dependency, and informational asymmetry, it may also be disproportionate insofar as it relies on prohibitions backed by sanctions in a domain where even beneficial uses may entail residual risks for fundamental rights such as privacy and data protection.
The central thesis of this study is that legitimate workplace uses of AI – particularly those aimed at improving safety, ergonomics, and organisational efficiency – should not be addressed predominantly through prohibition. Instead, higher levels of risk should trigger the implementation of more robust procedural and participatory safeguards, which are capable of mitigating the inherent structural asymmetries that are embedded within employment relationships.
This brings us to the role of labour law and fundamental rights in this context. Although instruments such as Directive 2002/14/EC (establishing a general framework for informing and consulting employees) already exist, they present significant limitations, notably in failing to address the enhanced opacity and informational asymmetry associated with AI systems, and in excluding substantial parts of the workforce. At the same time, although Member States play a pivotal role in this domain, a purely decentralised approach is inadequate, and several factors justify Union-level intervention. Firstly, the participatory and dialogical approach advocated here is difficult to reconcile with the AI Act’s compliance-and-sanctions model, which may encourage Member States to adopt similarly restrictive approaches. Consequently, a signal at EU level indicating a different direction would be advantageous. Secondly, the maintenance of the current framework carries with it the risk of suggesting that minimal information obligations are sufficient, which is not the case. Thirdly, the Union itself is responsible for social policy, as reflected in the Treaties, the Charter, the European Pillar of Social Rights, and case law.
The participatory approach advocated in this research should therefore encompass the following: (i) co-design and co-creation, ensuring that systems reflect real working conditions rather than abstract productivity metrics (Pereira et al., 2025); (ii) procedural co-determination and participation, structuring interaction between employers and worker representatives across all stages of implementation (Aloisi & De Stefano, 2023); and (iii) access to data and system logic, enabling meaningful understanding and contestation, supported by training and education (Petrat, 2021; Todolí-Signes, 2021).
It is only through this approach that AI systems can be regarded as anything other than a fixed product; rather, they should be considered socio-technical arrangements shaped through ongoing dialogue. From a regulatory perspective, the blog supports a shift towards more responsive forms of governance, combining guidance, cooperation, and incentives, with sanctions operating only as a last resort. It is hypothesised that the EU has a role to play in this regard, at least to ensure the coherence needed in this domain and a minimal level of protection for fundamental social rights. Pending the implementation of the aforementioned measures, it is incumbent upon both Member States and companies, as employers, to endeavour to incorporate this approach into their respective operations.
Next week, the series continues with the blog post “Unsettled Categories: Neurodata Processing in Occupational Safety and Health at the Boundaries of Data Protection” by José Miguel Diéguez Rodríguez, in which he analyses how existing EU legal frameworks should respond to the growing use of neurodevices in the workplace.